{"id":"CVE-2020-35702","details":"DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December 2020, not the 20.12.1 release. In this situation, it should NOT be considered a Poppler vulnerability. However, several third-party Open Source projects directly rely on Poppler git clones made at arbitrary times, and therefore the CVE remains useful to users of those projects","modified":"2026-07-08T17:56:15.893483Z","published":"2020-12-25T02:15:12.900Z","references":[{"type":"EVIDENCE","url":"https://gitlab.freedesktop.org/poppler/poppler/-/issues/1011"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.freedesktop.org/poppler/poppler","events":[{"introduced":"5d3e71c8215997a96d2ade7272217087f7e59fe2"},{"last_affected":"5d3e71c8215997a96d2ade7272217087f7e59fe2"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:freedesktop:poppler:20.12.1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"20.12.1"},{"last_affected":"20.12.1"}]}}],"versions":["20.12.1","poppler-20.12.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-35702.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}